Privacy Policy
Effective date: May 15, 2026
Last reviewed: May 15, 2026
Who we are
Money and Macros ("M&M," "we," "us") is operated by Money and Macros LLC, a limited liability company organized under the laws of Washington. Our mailing address is 522 W Riverside Ave Ste N, Spokane, WA 99201. You can reach us at hello@moneyandmacros.com.
This policy explains what personal information we collect when you use the M&M website, web app, and mobile apps (the "Service"), why we collect it, who we share it with, and the choices you have.
What we collect
We collect only what we need to operate the Service. Specifically:
- Account information. Email address and password (or third-party identifier if you sign in with Google or Apple), provided through our authentication provider Clerk.
- Financial data you enter or import.Account balances, transactions, budget categories, recurring bills, and similar entries you create manually. If you choose to connect a bank account (an optional feature available on paid plans), we also import transactions and balance information from that connection. See “Connecting your bank” below for details.
- Bank-connection data (optional). If you connect a bank via Plaid, we receive: the financial institution name, masked account numbers (last four digits only), account types, account balances, and transaction details (date, amount, merchant, Plaid category). We do not see or store your bank login credentials at any time.
- Nutrition data you enter. Food entries, macros, calorie targets, and related preferences.
- Photos and camera images.Receipts, food photos, and order screenshots you submit for AI processing — whether uploaded from your device or, in the mobile app, captured with your camera. Photos are used for extraction and then retained at your discretion.
- Usage data. Pages viewed, features used, device type, approximate location (from IP), and similar diagnostic data, used to improve the Service and detect abuse.
- Marketing analytics. On our public marketing pages only, we use Meta Pixel to measure ad performance (page views, completed sign-ups). The Pixel is not loaded inside the authenticated app.
- Communications. Feedback, support messages, and email replies you send us.
How we use your data
- To provide, secure, and improve the Service.
- To process the photos and screenshots you upload using AI to extract receipt or food information.
- To send transactional email (account verification, billing receipts, important notices).
- To detect, prevent, and respond to abuse, fraud, or security issues.
- To measure marketing performance for our own ads (aggregate; we do not target you individually).
- To comply with legal obligations.
We do not sell your personal information, and we do not share your financial or nutrition data with advertisers or data brokers.
Service providers we use
We rely on a small number of vetted vendors (sub-processors) to operate the Service. Each is bound by their own privacy and security commitments:
- Clerk — authentication and session management.
- Supabase — database and file storage for your account data, hosted in the United States.
- Vercel — application hosting and CDN.
- Anthropic (Claude) — AI processing of receipts, food photos, and order screenshots you upload.
- Resend — transactional email delivery.
- Meta (Facebook) — Pixel tracking on public marketing pages only, for ad measurement.
- Stripe— payment processing for paid plans (when active). Payment card details are sent directly to Stripe and are never stored by M&M.
- Plaid— financial data network used only when you opt in to bank-connect. Plaid handles the bank login and provides M&M with read-only transaction and balance data. Plaid’s end-user privacy notice: plaid.com/legal.
Connecting your bank (via Plaid)
Bank-connect is an optional feature. If you choose to use it, M&M partners with Plaid Inc. to securely pull transaction and balance data from your financial institution. Here’s how it works and what we want you to know:
- You authorize the connection.When you tap “Connect a bank,” Plaid’s secure interface opens. You enter your bank credentials directly into Plaid’s widget — M&M never sees your password. Plaid returns an encrypted access token to M&M which is used only to fetch the financial data described above.
- What we receive.Institution name, account types, the last four digits of each account number (masks), account balances at the moment of each sync, and transaction records (date, amount, merchant, Plaid’s suggested category).
- What we do with it.Imported data appears in your M&M ledger alongside any manual entries. We use it to power your dashboards, budgets, and analytics. Suggested categories from Plaid are treated as suggestions; your own categories always take precedence. We do not use bank data for advertising, do not share it with advertisers or data brokers, and do not sell it.
- How we secure the access token. The token Plaid issues is encrypted at rest in our database using industry-standard cryptography and is only decrypted server-side at the moment of a sync. It is never sent to the browser.
- Revoking access.You can disconnect your bank at any time from Settings → Connected institutions. Disconnecting pauses sync and revokes M&M’s access at Plaid; your imported transactions stay in your ledger by default. A separate “Delete data” option will, on explicit confirmation, remove all bank-imported transactions for that connection.
- What Plaid does with your data.Plaid’s use of your financial information is governed by their own privacy notice (linked above). M&M does not control Plaid’s practices; please review Plaid’s notice for full disclosure of how they handle your data.
- GLBA notice.Information we collect via Plaid is treated as “nonpublic personal information” under the Gramm-Leach-Bliley Act. We use it only for the purposes described in this notice, do not disclose it to nonaffiliated third parties for marketing, and protect it consistent with applicable security standards.
Cookies and similar tracking
We use a small number of cookies and similar technologies:
- Essential cookies — required for sign-in and session management (set by Clerk).
- First-party analytics — anonymous page-view records used to operate and improve the app.
- Marketing cookies — Meta Pixel, loaded only on public marketing pages, used to measure ad performance.
You can disable cookies in your browser, but doing so may break sign-in. Most browsers also offer a "Do Not Track" setting; we honor it where technically feasible.
Mobile app permissions
If you use the Money and Macros mobile app, the app may ask permission to use certain device features. You can grant or revoke each of these at any time in your device’s settings.
- Camera. Used only when you actively choose to scan a receipt, capture a food photo, or scan a barcode. The app does not access your camera in the background.
- Photos and media. Used only when you choose to upload an existing image, such as a receipt saved in your photo library. The app accesses only the specific photo you select, not your whole library.
- Biometric unlock (optional).If you turn on the optional app-lock, the app uses your device’s built-in Face ID, Touch ID, or fingerprint system to unlock M&M. This check happens entirely on your device. M&M never receives, sees, or stores your fingerprint, facial geometry, or any other biometric data — the device only reports whether authentication succeeded.
How long we keep your data
We retain your account data for as long as your account is active. If you delete your account, we delete or de-identify your personal data within 30 days, except where we are legally required to retain it (for example, transaction records for tax purposes).
Your rights
You can access, correct, export, or delete your data at any time. The simplest way is from inside the app, or by emailing hello@moneyandmacros.com. We will respond within 30 days.
California residents (CCPA/CPRA): you have the right to know what personal information we collect, request its deletion, request its correction, and opt out of its sale or sharing. We do not sell or share your personal information for cross-context behavioral advertising. You will not be discriminated against for exercising these rights.
Security
We protect your data with industry-standard measures: encrypted connections (TLS), encryption at rest, row-level database isolation so users cannot see each other's data, and rate limits on our APIs. No system is perfectly secure, but we work to minimize risk.
Children
The Service is not intended for children under 13, and we do not knowingly collect data from anyone under 13. If you believe a child has provided us with personal information, please contact us and we will delete it.
International users
The Service is operated from the United States. If you access it from outside the U.S., your data will be transferred to and processed in the U.S. and other countries where our service providers operate.
Changes to this policy
We may update this policy from time to time. If we make material changes, we will notify you by email or by a prominent notice in the app before the changes take effect. The "Effective date" at the top of this page reflects the most recent revision.
Contact us
Questions about this policy or your data? Email hello@moneyandmacros.com, or write to us at 522 W Riverside Ave Ste N, Spokane, WA 99201.